This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Coventry Structured Investments Supports Centurion Foundation’s Acquisition of Two Rhode Island Hospitals

Coventry Structured Investments Supports Centurion Foundation’s Acquisition of Two Rhode Island Hospitals

CSI [patiently] helped to enable The Centurion Foundation's acquisition of Roger Williams Medical Center and Our Lady

March 17, 2026

Window Film Depot Named 2025 3M National Dealer of the Year for Architectural Film Solutions

Window Film Depot Named 2025 3M National Dealer of the Year for Architectural Film Solutions

The award recognizes the nation’s top multi-market authorized installation contractor for building window film

March 17, 2026

Pervaziv AI Launches Cortex 3.0 in Chrome, Edge and Firefox – World’s First Cross-Browser/IDE AI Coding & Security Agent

Pervaziv AI Launches Cortex 3.0 in Chrome, Edge and Firefox – World’s First Cross-Browser/IDE AI Coding & Security Agent

Cortex 3.0 delivers AI-powered code generation, vulnerability scanning, Enterprise AI & DevSecOps integrations,

March 17, 2026

BCR Cyber to Provide Instruction for Maryland Workforce Association’s Cybersecurity Support Technician Apprenticeships

BCR Cyber to Provide Instruction for Maryland Workforce Association’s Cybersecurity Support Technician Apprenticeships

BALTIMORE, MD, UNITED STATES, March 17, 2026 /EINPresswire.com/ — BCR Cyber, a leading provider of comprehensive cyber

March 17, 2026

Influential Women Features Claudia Felizitas Granger: Coach Guiding Professionals To Purpose And Fulfillment

Influential Women Features Claudia Felizitas Granger: Coach Guiding Professionals To Purpose And Fulfillment

MOUNT IDA, AR, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Founder of AlchemizedCareer™ Helps High-Achieving

March 17, 2026

Phifer and Company Releases 2026 Communications & Marketing Salary Guide

Phifer and Company Releases 2026 Communications & Marketing Salary Guide

New data from Phifer & Company reveals 2026 salary trends shaping Communications, Marketing, Branding, and

March 17, 2026

NEW color2go from BYK-Gardner USA

NEW color2go from BYK-Gardner USA

Portable color and gloss measurement with digital standards The NEW color2go, portable spectrophotometer combines

March 17, 2026

Liquid Lemon Launches Shopify Design Studio for DTC Brands

Liquid Lemon Launches Shopify Design Studio for DTC Brands

The new studio delivers fully custom Shopify storefronts in 30 days at a fixed price of $7,500, trusted by Gymshark,

March 17, 2026

The Travel Society Honors Top Advisors and Partners at Annual Summit, Reinforcing Boutique Luxury Leadership

The Travel Society Honors Top Advisors and Partners at Annual Summit, Reinforcing Boutique Luxury Leadership

Nearly 40-year travel industry leader and Virtuoso member honors advisor excellence, longevity, and strategic vendor

March 17, 2026

Keystone Marble & Granite Enhances Custom Countertop Fabrication Services in PA & NJ

Keystone Marble & Granite Enhances Custom Countertop Fabrication Services in PA & NJ

Keystone Marble & Granite expands custom countertop fabrication in PA & NJ with precision cutting, premium

March 17, 2026

Optimum Pest Control Expands Professional Rat Control Services in NYC

Optimum Pest Control Expands Professional Rat Control Services in NYC

Optimum Pest Control expands rat control services in NYC with fast inspections, targeted treatments, and prevention

March 17, 2026

CMG Containers Expands Refrigerated Containers for Sale to Support Temperature-Controlled Storage and Transport

CMG Containers Expands Refrigerated Containers for Sale to Support Temperature-Controlled Storage and Transport

CMG Containers expands refrigerated container inventory, helping customers secure reliable temperature-controlled

March 17, 2026

Patient Protect Launches Signal, a Free Healthcare Cybersecurity and HIPAA Intelligence App for Providers

Patient Protect Launches Signal, a Free Healthcare Cybersecurity and HIPAA Intelligence App for Providers

Free mobile app delivers breach intelligence, compliance tools, and shared threat awareness for independent healthcare

March 17, 2026

IT-Harvest Publishes Guardians of the Machine Age: Why AI Security Will Define the Future of Digital Defense

IT-Harvest Publishes Guardians of the Machine Age: Why AI Security Will Define the Future of Digital Defense

A timely new book explores why artificial intelligence is changing the entire security industry landscape. It's

March 17, 2026

Influential Women Highlights Denise Meyer, Ed.D., MBA, PMP: Founder Of Denise Meyer Consulting And Project Solutions

Influential Women Highlights Denise Meyer, Ed.D., MBA, PMP: Founder Of Denise Meyer Consulting And Project Solutions

CHICAGO, IL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Driving Organizational Impact Through Strategic

March 17, 2026

Blend Media Reports Rising Demand for Scenario-Based Corporate Training

Blend Media Reports Rising Demand for Scenario-Based Corporate Training

Wyoming-based instructional design studio sees increased interest from hospitality and retail sectors seeking

March 17, 2026

OptraSCAN Launches HistoSiA™ Breast Pay-Per-Use: Scan, Analyze & Auto-Segregate Breast Cancer IHC Cases in One Workflow

OptraSCAN Launches HistoSiA™ Breast Pay-Per-Use: Scan, Analyze & Auto-Segregate Breast Cancer IHC Cases in One Workflow

AI-enabled platform auto-categorizes HER2 cases during scanning, allowing pathologists to review pre-analyzed results

March 17, 2026

Solix and Symbiosis (SCEI & SMCW) Partner to Launch Center of Excellence for New Drug Discovery and Repurposing

Solix and Symbiosis (SCEI & SMCW) Partner to Launch Center of Excellence for New Drug Discovery and Repurposing

Strengthening collaboration to drive innovation across AI, biomedical research, and translational medicine PUNE,

March 17, 2026

Health Recovery Solutions Appoints Dr. Lucienne Ide as Chief Medical Officer Following Rimidi Acquisition

Health Recovery Solutions Appoints Dr. Lucienne Ide as Chief Medical Officer Following Rimidi Acquisition

Appointment of Rimidi founder Dr. Lucienne Ide as CMO strengthens HRS’s clinical leadership and advances their vision

March 17, 2026

From Immigrant to Cavaliere: Altomonte’s Franca Grispino Named Knight of the Italian Republic

From Immigrant to Cavaliere: Altomonte’s Franca Grispino Named Knight of the Italian Republic

From Immigrant to Cavaliere: Altomonte’s Matriarch Franca Grispino Named a Knight of the Italian Republic in Market’s

March 17, 2026

Noteworthy AI Achieves SOC 2 Type I Attestation to Support Secure, Scalable Utility Deployments

Noteworthy AI Achieves SOC 2 Type I Attestation to Support Secure, Scalable Utility Deployments

Milestone will help utilities simplify vendor onboarding and securely scale AI-powered grid intelligence across

March 17, 2026

OneKey® MLS February Data Reveals Rising Prices and Quicker Sales Across New York Metro Area

OneKey® MLS February Data Reveals Rising Prices and Quicker Sales Across New York Metro Area

Median home values rose across all property types, even as a shrinking supply of listings kept transaction volume in

March 17, 2026

2027 International Indigenous Games & Gathering Partners with Success Beyond Game Day to Launch Global Indigenous Youth Leadership Initiative

2027 International Indigenous Games & Gathering Partners with Success Beyond Game Day to Launch Global Indigenous Youth Leadership Initiative

This partnership integrates SBGD's athlete identity development & mentorship programming with IIGG’s Indigenous-led

March 17, 2026

Longevity Health Holdings Closes Strategic Investment and Appoints Ram Ajjarapu as Chairman and CEO to Drive Growth

Longevity Health Holdings Closes Strategic Investment and Appoints Ram Ajjarapu as Chairman and CEO to Drive Growth

Longevity Health Holdings Closes Strategic Investment and Appoints Ram Ajjarapu as Chairman and CEO to Drive

March 17, 2026

Heroes Made Now Available to Texas Schools to Support Character Education Within Existing Instructional Time

Heroes Made Now Available to Texas Schools to Support Character Education Within Existing Instructional Time

Heroes Made integrates into existing class time with zero prep, helping Texas elementary schools build character,

March 17, 2026

FMUSER Launches CB100 18ft High-Gain 27MHz CB Base Antenna Optimized for Solar Cycle 25 DX Emergency Radio Communication

FMUSER Launches CB100 18ft High-Gain 27MHz CB Base Antenna Optimized for Solar Cycle 25 DX Emergency Radio Communication

This professional-grade 1/2 wave aluminum antenna is designed to enhance 27MHz signal clarity and transmission range

March 17, 2026

Pamela Kan Receives Leadership and Empowerment Award at 2026 East Bay Women’s Conference

Pamela Kan Receives Leadership and Empowerment Award at 2026 East Bay Women’s Conference

Pamela Kan, CEO of Bishop-Wisecarver, received the 2026 East Bay Women’s Conference Leadership & Empowerment Award

March 17, 2026

Influential Women Highlights Lourdes Lulu Buck, M.A.: Educational Leader, Children’s Author, And Equity Advocate

Influential Women Highlights Lourdes Lulu Buck, M.A.: Educational Leader, Children’s Author, And Equity Advocate

LONGMONT, CO, UNITED STATES, March 17, 2026 /EINPresswire.com/ — District Coordinator of Student Services at St. Vrain

March 17, 2026

Best Homes LLC of Florida Expands Awareness of Its 1% Full-Service Real Estate Model Across Florida

Best Homes LLC of Florida Expands Awareness of Its 1% Full-Service Real Estate Model Across Florida

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Best Homes LLC of Florida, is continuing to expand awareness of

March 17, 2026

OpenLight and TFC Advance Silicon Photonics Back End Integration Supporting up to 400G Data Rates on TGV Substrate

OpenLight and TFC Advance Silicon Photonics Back End Integration Supporting up to 400G Data Rates on TGV Substrate

As silicon photonics adoption continues to grow, success increasingly depends on the readiness of the back end

March 17, 2026

Pop anthem goes viral Taking Modern Tamil Literature Global

Pop anthem goes viral Taking Modern Tamil Literature Global

NEW YORK, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — A vibrant new pop anthem created for the upcoming

March 17, 2026

Influential Women Profiles Naomi Withers, EMBA, CHPC: High Performance Coach And Strategic Advisor

Influential Women Profiles Naomi Withers, EMBA, CHPC: High Performance Coach And Strategic Advisor

MCKINLEYVILLE, CA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Empowering Leaders and Organizations Through

March 17, 2026

Physician-Governed Innovative Health ACO Established to Advance Clinical Collaboration and Value-Based Care Readiness

Physician-Governed Innovative Health ACO Established to Advance Clinical Collaboration and Value-Based Care Readiness

ACO formation emphasizes independent physician leadership, patient-centered outcomes, and coordinated care. TAMPA, FL,

March 17, 2026

High-Resolution Airborne Survey Completed at Music Valley HREE Project

High-Resolution Airborne Survey Completed at Music Valley HREE Project

Mapping and sampling underway to refine geological model SAN BERNARDINO, CA / ACCESS Newswire / March 17, 2026 /

March 17, 2026

TRNR Exhibits at HFA 2026 with All Four Brands and Strong Leadership Presence

TRNR Exhibits at HFA 2026 with All Four Brands and Strong Leadership Presence

TRNR Now Operates Four Premium Fitness Brands Following Acquisition of Ergatta, Leading to Increased Guidance of more

March 17, 2026

Regentis Biomaterials Develops and Patents New Solvent-Free Manufacturing Process That Increases GelrinC Production Yield by 400%

Regentis Biomaterials Develops and Patents New Solvent-Free Manufacturing Process That Increases GelrinC Production Yield by 400%

Breakthrough manufacturing process comes in preparation for upcoming commercial launch in Europe planned for later this

March 17, 2026

Aspire Biopharma’s Subsidiary, Buzz Bomb Caffeine Company, Appoints John Choe as Western Sales Director

Aspire Biopharma’s Subsidiary, Buzz Bomb Caffeine Company, Appoints John Choe as Western Sales Director

ESTERO, FL / ACCESS Newswire / March 17, 2026 / Aspire Biopharma Holdings, Inc. (Nasdaq:ASBP) ("Aspire"), wholly owned

March 17, 2026

Influential Women Profiles Nikita Bhosale: Driving Excellence in Global Supply Chain Operations

Influential Women Profiles Nikita Bhosale: Driving Excellence in Global Supply Chain Operations

LITTLE FALLS, NJ, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Senior Product Supply Project Manager at Bayer

March 17, 2026

Levinson Axelrod Expands Presence in South Jersey With New Cherry Hill Office

Levinson Axelrod Expands Presence in South Jersey With New Cherry Hill Office

New location brings the firm’s 86+ years of courtroom-first advocacy closer to families across Camden County and

March 17, 2026

Polar Data Centers and Vertiv win ‘Most Successfully Delivered Data Centre’ award.

Polar Data Centers and Vertiv win ‘Most Successfully Delivered Data Centre’ award.

DCW award recognizes the successful delivery of DRA01, a 12MW next-generation AI-ready facility in Norway. This award

March 17, 2026